<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=26&amp;t=1665" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2014-12-17T21:18:28+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=26&amp;t=1665</id>
<entry>
<author><name><![CDATA[FlorinAndrei]]></name></author>
<updated>2014-12-17T21:18:28+01:00</updated>
<published>2014-12-17T21:18:28+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1665&amp;p=6565#p6565</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1665&amp;p=6565#p6565"/>
<title type="html"><![CDATA[Re: [Q?] is the NEO smartcard accessible from VirtualBox gue]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1665&amp;p=6565#p6565"><![CDATA[
On OS X 10.9 there was a pcscd IIRC, but that seems to be gone.<br /><br />On 10.10 there's a process that seems to run all the time:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">/System/Library/Frameworks/PCSC.framework/Versions/A/XPCServices/com.apple.ctkpcscd.xpc/Contents/MacOS/com.apple.ctkpcscd<br /></div><br />When you use the NEO smartcard for the first time with gpg-agent and ssh, the list of related processes grows:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">/System/Library/Frameworks/PCSC.framework/Versions/A/XPCServices/com.apple.ctkpcscd.xpc/Contents/MacOS/com.apple.ctkpcscd<br /><br />pcsc-wrapper -- 1 /System/Library/Frameworks/PCSC.framework/PCSC<br /><br />/System/Library/Frameworks/PCSC.framework/Versions/A/XPCServices/com.apple.ctkpcscd.xpc/Contents/MacOS/com.apple.ctkpcscd</div><br /><br />In any case, I can't seem to make it work from the guest. The extra two processes are not even launched when I try to use the smartcard from the guest. Moreover, having the guest running with the USB filter for NEO prevents the smartcard from working correctly with gpg-agent on the host itself. No idea why. Disable those filters and the guest does not interfere with the smartcard and gpg-agent on the host anymore.<br /><br />---<br /><br />There is a workaround:<br /><br />Don't do anything on the guest. On the host, enable &quot;ForwardAgent yes&quot; for the range of IPs where the guests are. Then ssh from the host to the guest.<br /><br />Now, on the guest, if you try to ssh anywhere, the authentication requests will be forwarded back to the host through the ssh chain. If gpg-agent is enabled on the host, your guest-run ssh session will be authenticated against the smartcard.<br /><br />Of course, for this to work, before all you must ssh into the guest from the host. And then you're still subject to the smartcard issues that are plaguing OS X 10.10, like this one:<br /><br /><!-- l --><a class="postlink-local" href="http://forum.yubico.com/viewtopic.php?f=26&amp;t=1656">viewtopic.php?f=26&amp;t=1656</a><!-- l --><br /><br />Perhaps those issues are what cause the guest to not be able to use the NEO plugged into the host. I don't have a way to tell for sure.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2986">FlorinAndrei</a> — Wed Dec 17, 2014 9:18 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Klas]]></name></author>
<updated>2014-12-17T15:26:35+01:00</updated>
<published>2014-12-17T15:26:35+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1665&amp;p=6556#p6556</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1665&amp;p=6556#p6556"/>
<title type="html"><![CDATA[Re: [Q?] is the NEO smartcard accessible from VirtualBox gue]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1665&amp;p=6556#p6556"><![CDATA[
My experience with VirtualBox and smartcards have been a bit hit and miss. With a linux host it works ok if pcscd is stopped on the host, in other cases the device does not seem to be handed over correctly.<br /><br />I've had some luck with creating an auto rule for a device to get passed through.<br /><br />/klas<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2019">Klas</a> — Wed Dec 17, 2014 3:26 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[darco]]></name></author>
<updated>2014-12-17T03:26:28+01:00</updated>
<published>2014-12-17T03:26:28+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1665&amp;p=6543#p6543</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1665&amp;p=6543#p6543"/>
<title type="html"><![CDATA[Re: [Q?] is the NEO smartcard accessible from VirtualBox gue]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1665&amp;p=6543#p6543"><![CDATA[
Do you not then see the USB device in your VM?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3288">darco</a> — Wed Dec 17, 2014 3:26 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[FlorinAndrei]]></name></author>
<updated>2014-12-17T02:57:10+01:00</updated>
<published>2014-12-17T02:57:10+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1665&amp;p=6541#p6541</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1665&amp;p=6541#p6541"/>
<title type="html"><![CDATA[Re: [Q?] is the NEO smartcard accessible from VirtualBox gue]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1665&amp;p=6541#p6541"><![CDATA[
The Extension Pack? It's installed already.<br /><br />I've also tried to create / add a USB filter for this instance for that specific USB device - still nothing.<br /><br />neo.png<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2986">FlorinAndrei</a> — Wed Dec 17, 2014 2:57 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[darco]]></name></author>
<updated>2014-12-17T02:47:12+01:00</updated>
<published>2014-12-17T02:47:12+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1665&amp;p=6540#p6540</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1665&amp;p=6540#p6540"/>
<title type="html"><![CDATA[Re: [Q?] is the NEO smartcard accessible from VirtualBox gue]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1665&amp;p=6540#p6540"><![CDATA[
I think you need the extra USB stuff for virtual box (sorry, can't remember the package name). Then you can delegate specific USB devices to be used by the virtual machine.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3288">darco</a> — Wed Dec 17, 2014 2:47 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[FlorinAndrei]]></name></author>
<updated>2014-12-17T01:35:20+01:00</updated>
<published>2014-12-17T01:35:20+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1665&amp;p=6537#p6537</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1665&amp;p=6537#p6537"/>
<title type="html"><![CDATA[[Q?] is the NEO smartcard accessible from VirtualBox guest?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1665&amp;p=6537#p6537"><![CDATA[
My host system is OS X 10.10. I use VirtualBox, currently version 4.3.20. I have various guest OSs in VBox, for example Fedora 17. If the NEO token is plugged into the OS X host, would the smartcard portion of the token be available from the Linux guest in VBox?<br /><br />The smartcard is operational and I can use it from the OS X host to authenticate ssh sessions, via gpg-agent and the key stored on the smartcard - that works great. USB options are all enabled for the Fedora 17 guest. I've enabled gpg-agent on the guest the same way I did on the host.<br /><br />Yet gpg-agent on the guest cannot seem to access the NEO plugged into the host. It just falls back on password authentication. Anything else I need to do / configure / change / enable?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2986">FlorinAndrei</a> — Wed Dec 17, 2014 1:35 am</p><hr />
]]></content>
</entry>
</feed>